VYPR

Vendor CVEs

Eclipse

All CVEs

356 total · sorted by risk
  • CVE-2026-12856HigJun 29, 2026
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extension incorrectly trusts all Markdown content in JavaDoc hovers, allowing a malicious Java file to include hidden commands. If a user clicks a specially crafted…

  • CVE-2026-9158CriJun 18, 2026
    risk 0.57cvss 9.8epss 0.01

    In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subsequent commands to access freed memory (use-after-free).

  • CVE-2023-4759HigSep 12, 2023
    risk 0.57cvss 8.8epss 0.02

    Arbitrary File Overwrite in Eclipse JGit <= 6.6.0 In Eclipse JGit, all versions <= 6.6.0.202305301015-r, a symbolic link present in a specially crafted git repository can be used to write a file to locations outside the working tree when this repository is cloned with JGit to a…

  • CVE-2020-27220HigJan 14, 2021
    risk 0.57cvss 8.8epss 0.01

    The Eclipse Hono AMQP and MQTT protocol adapters do not check whether an authenticated gateway device is authorized to receive command & control messages when it has subscribed only to commands for a specific device. The missing check involves verifying that the command target…

  • CVE-2019-17640CriOct 15, 2020
    risk 0.57cvss 9.8epss 0.02

    In Eclipse Vert.x 3.4.x up to 3.9.4, 4.0.0.milestone1, 4.0.0.milestone2, 4.0.0.milestone3, 4.0.0.milestone4, 4.0.0.milestone5, 4.0.0.Beta1, 4.0.0.Beta2, and 4.0.0.Beta3, StaticHandler doesn't correctly processes back slashes on Windows Operating systems, allowing, escape the…

  • CVE-2019-17633HigDec 19, 2019
    risk 0.57cvss 8.8epss 0.01

    For Eclipse Che versions 6.16 to 7.3.0, with both authentication and TLS disabled, visiting a malicious web site could trigger the start of an arbitrary Che workspace. Che with no authentication and no TLS is not usually deployed on a public network but is often used for local…

  • CVE-2018-12544CriOct 10, 2018
    risk 0.57cvss 9.8epss 0.02

    In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense against XML attacks. This mechanism is exclusively when the developer uses the Eclipse Vert.x OpenAPI XML type validator to validate a…

  • CVE-2018-12542CriOct 10, 2018
    risk 0.57cvss 9.8epss 0.02

    In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '\' (forward slashes) sequences that can resolve to a location that is outside of…

  • CVE-2018-12538HigJun 22, 2018
    risk 0.57cvss 8.8epss 0.03

    In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the…

  • CVE-2022-39293HigOct 13, 2022
    risk 0.56cvss 8.6epss 0.01

    Azure RTOS USBX is a high-performance USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. The case is, in [_ux_host_class_pima_read](https://github.com/azure-rtos/usbx/blob/master/common/usbx_host_classes/src/ux_host_class_pima_…

  • CVE-2026-6272HigApr 24, 2026
    risk 0.55cvss —epss 0.00

    A client holding only a read JWT scope can still register itself as a signal provider through the production kuksa.val.v2 OpenProviderStream API by sending ProvideSignalRequest. 1. Obtain any valid token with only read scope. 2. Connect to the normal production gRPC API…

  • CVE-2019-17638CriJul 9, 2020
    risk 0.55cvss 9.4epss 0.11

    In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce an HTTP 431 error. When this happens, the ByteBuffer containing the HTTP response headers is released back to the ByteBufferPool twice.…

  • CVE-2026-19203HigSep 8, 2026
    risk 0.54cvss —epss 0.00

    A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, potentially resulting in HTTP request smuggling. This is caused by Jetty accepting a lone LF character as a…

  • CVE-2026-9561HigJul 14, 2026
    risk 0.53cvss 8.2epss 0.00

    Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log entries. The org.eclipse.kura.web2 (Web Console) and org.eclipse.kura.rest.provider (REST API) components use this header…

  • CVE-2021-41034HigSep 29, 2021
    risk 0.53cvss 8.1epss 0.00

    The build of some language stacks of Eclipse Che version 6 includes pulling some binaries from an unsecured HTTP endpoint. As a consequence the builds of such stacks are vulnerable to MITM attacks that allow the replacement of the original binaries with arbitrary ones. The…

  • CVE-2021-41033HigSep 13, 2021
    risk 0.53cvss 8.1epss 0.01

    In all released versions of Eclipse Equinox, at least until version 4.21 (September 2021), installation can be vulnerable to man-in-the-middle attack if using p2 repos that are HTTP; that can then be exploited to serve incorrect p2 metadata and entirely alter the local…

  • CVE-2021-32834HigSep 9, 2021
    risk 0.53cvss 8.2epss 0.01

    Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a user able to create Policy Sets can run arbitrary code by sending malicious Groovy scripts which will escape the configured Groovy sandbox. This…

  • CVE-2021-28165HigApr 1, 2021
    risk 0.53cvss 7.5epss 0.54

    In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.

  • CVE-2019-11770HigJun 14, 2019
    risk 0.53cvss 8.1epss 0.01

    In Eclipse Buildship versions prior to 3.1.1, the build files indicate that this project is resolving dependencies over HTTP instead of HTTPS. Any of these artifacts could have been MITM to maliciously compromise them and infect the build artifacts that were produced.…

  • CVE-2019-10248HigApr 22, 2019
    risk 0.53cvss 8.1epss 0.00

    Eclipse Vorto versions prior to 0.11 resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by a MITM attack. Hence produced build artifacts of Vorto might be infected.

  • CVE-2019-10240HigApr 3, 2019
    risk 0.53cvss 8.1epss 0.00

    Eclipse hawkBit versions prior to 0.3.0M2 resolved Maven build artifacts for the Vaadin based UI over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by a MITM attack. Hence produced build artifacts of hawkBit might be infected.

  • CVE-2018-12551HigMar 27, 2019
    risk 0.53cvss 8.1epss 0.01

    When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use a password file for authentication, any malformed data in the password file will be treated as valid. This typically means that the malformed data becomes a username and no password. If this occurs,…

  • CVE-2018-12550HigMar 27, 2019
    risk 0.53cvss 8.1epss 0.01

    When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use an ACL file, and that ACL file is empty, or contains only comments or blank lines, then Mosquitto will treat this as though no ACL file has been defined and use a default allow policy. The new behaviour…

  • CVE-2026-78299CriSep 14, 2026
    risk 0.52cvss 9.1epss 0.00

    In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on disk.

  • CVE-2026-82955CriSep 2, 2026
    risk 0.52cvss —epss 0.00

    In the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API Gateway component had the disable_jwk_security parameter hard-coded to true, with no option to override it through the Helm chart…

  • CVE-2026-18918CriAug 28, 2026
    risk 0.52cvss —epss 0.00

    In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server authorization checks can be bypassed when the 2-legged auth is supported by the server. In those cases, application that based their authz filters upon Lyo-provided `AbstractAdapterCredentialsFilter`, are vulnerable. An…

  • CVE-2026-10050CriAug 4, 2026
    risk 0.52cvss 9.1epss 0.00

    In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons. If…

  • CVE-2022-40187HigOct 13, 2022
    risk 0.52cvss 8.0epss 0.01

    Foresight GC3 Launch Monitor 1.3.15.68 ships with a Target Communication Framework (TCF) service enabled. This service listens on a TCP port on all interfaces and allows for process debugging, file system modification, and terminal access as the root user. In conjunction with a…

  • CVE-2018-12543HigNov 15, 2018
    risk 0.52cvss 7.5epss 0.34

    In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is not $SYS, e.g. $test/test, then an assert is triggered that should otherwise not be reachable and Mosquitto will exit.

  • CVE-2026-0648HigJan 27, 2026
    risk 0.51cvss 7.8epss 0.00

    The vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in threadx/utility/rtos_compatibility_layers/OSEK/tx_osek.c) when handling the return value of osek_get_counter(). Specifically, the current code checks if cntr_id equals 0u to…

  • CVE-2020-27225HigMar 9, 2021
    risk 0.51cvss 7.8epss 0.00

    In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to the local help web server, allowing an unauthenticated local attacker to issue active help commands to the associated Eclipse Platform process or Eclipse Rich…

  • CVE-2019-17635HigJan 17, 2020
    risk 0.51cvss 7.8epss 0.01

    Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a deserialization vulnerability if an index file of a parsed heap dump is replaced by a malicious version and the heap dump is reopened in Memory Analyzer. The user must chose to reopen an already parsed heap dump…

  • CVE-2019-11773HigSep 12, 2019
    risk 0.51cvss 7.8epss 0.00

    Prior to 0.1, AIX builds of Eclipse OMR contain unused RPATHs which may facilitate code injection and privilege elevation by local users.

  • CVE-2019-11771HigJul 17, 2019
    risk 0.51cvss 7.8epss 0.00

    AIX builds of Eclipse OpenJ9 before 0.15.0 contain unused RPATHs which may facilitate code injection and privilege elevation by local users.

  • CVE-2018-12539HigAug 14, 2018
    risk 0.51cvss 7.8epss 0.01

    In Eclipse OpenJ9 version 0.8, users other than the process owner may be able to use Java Attach API to connect to an Eclipse OpenJ9 or IBM JVM on the same machine and use Attach API operations, which includes the ability to execute untrusted native code. Attach API is enabled…

  • CVE-2026-85199HigSep 3, 2026
    risk 0.50cvss —epss 0.01

    Eclipse aeriOS Self-orchestrator versions prior to 1.2.1 contain a path traversal vulnerability in the REST API. User-controlled identifiers used to create, update, or delete Self-orchestrator resources were incorporated into filesystem paths without adequate validation or…

  • CVE-2026-82217HigAug 31, 2026
    risk 0.50cvss 8.8epss 0.00

    In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agent Mode" file-change tools (writeFileContent, suggestFileContent, and the replacement and state helpers) resolved a model-supplied file path without a workspace-containment check. A crafted relative path…

  • CVE-2026-10054HigJul 3, 2026
    risk 0.50cvss 8.8epss 0.00

    In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSocket (/services/shell-terminal, /services/terminals/:id) without service-level authentication. WebSocket origin validation in @theia/core is fail-open:…

  • CVE-2026-46580HigJun 18, 2026
    risk 0.50cvss 8.8epss 0.01

    In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the AI agent's system prompts. An attacker could craft a malicious repository containing prompt template files…

  • CVE-2026-44691HigJun 18, 2026
    risk 0.50cvss 8.8epss 0.00

    In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed without requiring workspace trust. An attacker could craft a malicious repository that, when cloned and opened in Theia, leads to…

  • CVE-2026-44688HigJun 18, 2026
    risk 0.50cvss 8.8epss 0.01

    In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing them from system instructions. An attacker could craft a malicious repository with adversarial directory or file names…

  • CVE-2023-0100HigMar 15, 2023
    risk 0.50cvss 8.8epss 0.01

    In Eclipse BIRT, starting from version 2.6.2, the default configuration allowed to retrieve a report from the same host using an absolute HTTP path for the report parameter (e.g. __report=http://xyz.com/report.rptdesign). If the host indicated in the __report parameter matched…

  • CVE-2022-36063HigOct 10, 2022
    risk 0.50cvss 7.6epss 0.02

    Azure RTOS USBx is a USB host, device, and on-the-go (OTG) embedded stack, fully integrated with Azure RTOS ThreadX and available for all Azure RTOS ThreadX–supported processors. Azure RTOS USBX implementation of host support for USB CDC ECM includes an integer underflow and a…

  • CVE-2021-34435HigSep 1, 2021
    risk 0.50cvss 8.8epss 0.01

    In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE. But with the way it is made it is possible for a previewed HTML file to trigger an RCE. This exploit only happens if a user previews a malicious file..

  • CVE-2019-18213HigOct 23, 2019
    risk 0.50cvss 8.8epss 0.02

    XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows XXE via a crafted XML document, with resultant SSRF (as well as SMB connection initiation that can lead to NetNTLM…

  • CVE-2018-12540HigJul 12, 2018
    risk 0.50cvss 8.8epss 0.02

    In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returned XSRF header/form parameter. This allows replay attacks with previously issued tokens which are not expired yet.

  • CVE-2026-47889HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19

  • CVE-2026-61891HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /files/`) that convert a client-supplied URI directly to a filesystem path and stream the file, without confining it to…

  • CVE-2026-46581HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the…

  • CVE-2026-12609HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlugin/:pluginId/:path(*)` HTTP endpoint, which resolves the requested file path with `path.resolve(localPath, filePath)` without verifying that the resolved path…

Page 2 of 8